Unrated severityNVD Advisory· Published Oct 23, 2018· Updated Aug 5, 2024
CVE-2018-18585
CVE-2018-18585
Description
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
Affected products
7- osv-coords7 versionspkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/libmspack&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 0.6-3.3.11+ 6 more
- (no CPE)range: < 0.6-3.3.11
- (no CPE)range: < 0.0.20060920alpha-74.11.6.1
- (no CPE)range: < 0.4-15.7.1
- (no CPE)range: < 0.0.20060920alpha-74.11.6.1
- (no CPE)range: < 0.4-15.7.1
- (no CPE)range: < 0.0.20060920alpha-74.11.6.1
- (no CPE)range: < 0.4-15.7.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- access.redhat.com/errata/RHSA-2019:2049mitrevendor-advisory
- security.gentoo.org/glsa/201903-20mitrevendor-advisory
- usn.ubuntu.com/3814-1/mitrevendor-advisory
- usn.ubuntu.com/3814-2/mitrevendor-advisory
- usn.ubuntu.com/3814-3/mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2018/10/msg00017.htmlmitremailing-list
- bugs.debian.org/911637mitre
- github.com/kyz/libmspack/commit/8759da8db6ec9e866cb8eb143313f397f925bb4fmitre
- www.openwall.com/lists/oss-security/2018/10/22/1mitre
- www.starwindsoftware.com/security/sw-20181213-0002/mitre
News mentions
0No linked articles in our index yet.